Vulnerability Description
Softr v2.0 was discovered to be vulnerable to HTML injection via the Name field of the Account page.
CVSS Score
9.8
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Softr | Softr | 2.0 |
Related Weaknesses (CWE)
References
- http://softr.comProduct
- https://isaghojaria.medium.com/softr-v2-0-was-discovered-to-be-vulnerable-to-htmExploitThird Party Advisory
- https://www.softr.io/Product
- http://softr.comProduct
- https://isaghojaria.medium.com/softr-v2-0-was-discovered-to-be-vulnerable-to-htmExploitThird Party Advisory
- https://www.softr.io/Product
FAQ
What is CVE-2022-40434?
CVE-2022-40434 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Softr v2.0 was discovered to be vulnerable to HTML injection via the Name field of the Account page.
How severe is CVE-2022-40434?
CVE-2022-40434 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2022-40434?
Check the references section above for vendor advisories and patch information. Affected products include: Softr Softr.